coinbasewalletcloud[.]created[.]app
Análisis de phishing y seguridad de coinbasewalletcloud.created.app
“Coinbase Wallet Extension – Connect to dApps Seamlessly”
coinbasewalletcloud.created.app — Contenido no disponible (HTTP 404). Suplantación de marca: Coinbase; Tipo de estafa: Aml Scam. Resumen de las pruebas: VirusTotal 9/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, CyRadar, ESET); Google Safe Browsing flagged; Spamhaus DBL_PHISH; PhishDestroy score 80/100. Registrador: Tucows.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain coinbasewalletcloud.created.app was registered through Tucows Domains Inc. on July 12, 2023 and is currently marked offline. DNS resolution points to the IP address 216.150.16.1, which belongs to Amazon.com, Inc. (AS16509) in the United States. The authoritative name servers are ns1.vercel-dns.com and ns2.vercel-dns.com, indicating that the site was hosted on the Vercel platform. Vercel detection correlates with the presence of HTTP Strict Transport Security (HSTS) and a valid SSL certificate issued by Let’s Encrypt (R13).
An HTTP request to the domain returns a 404 status code, suggesting that the malicious landing page is no longer accessible. The page title observed in historical records reads "Coinbase Wallet Extension – Connect to dApps Seamlessly," directly referencing Coinbase and reinforcing the brand impersonation claim. Google Safe Browsing flags the domain for social engineering, and VirusTotal records nine positive detections out of ninety‑five scanned scanners, confirming malicious activity. The domain appears on one security blocklist and has been actively blocked by PhishDestroy.
The identified threat aligns with an investment‑scam narrative targeting Coinbase users. Analysts should treat the infrastructure as compromised: block the domain and its associated IP at perimeter defenses, add the domain to internal phishing and malware blocklists, and monitor for other Vercel‑hosted subdomains that reference Coinbase or cryptocurrency services. Continuous observation of Amazon‑owned IP ranges for similar patterns is advised, as threat actors often recycle cloud resources. Because the site is offline, takedown verification is not possible, but the documented evidence warrants proactive defensive measures to prevent future exploitation of the same hosting configuration.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Registration: created.app
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain created.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 2 identified
Vercel is a cloud platform for static frontends and serverless functions.
vercel.com 100 % de confianzaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % de confianzaAnálisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.